Coolify
After four quiet months, Coolify's v4.4 candidate arrives carrying single sign-on.
◆Recent moves
- 28d ago
First v4.4 candidate adds first-class OpenID Connect sign-on
The first v4.4 release candidate, and the first entry in four months, built around first-class OIDC: discovery, JWKS key resolution, token validation, PKCE, identity linking, registration-policy controls, and optional auto-join to the root team. Team-scoped integration tokens arrive with it. This is the enterprise access layer the earlier hardening betas were clearing the ground for, though it ships as a candidate explicitly not for production, so the stable v4.4 is where it counts.
- 4mo ago
Beta 474: data-loss guard for pruned containers, encrypted webhook secrets
v4.0.0-beta.474 prevents data loss when persistent containers are pruned, encrypts manual webhook secrets, and fixes S3 backup endpoints under the API. The persistent-container fix in particular addresses a long-standing footgun in self-hosted deployments.
- 4mo ago
Beta 474 (duplicate publish)
Cross-feed duplicate of beta.474 — same release published a few hours apart. No additional content.
View source ↗ - 5mo ago
Beta 473: upgrade modal + Git source cleanup fixes
Beta.473 is a small fixup release: upgrade modal showing correct version, safe cleanup of team-owned Git app sources on user deletion. Cleanup work, not new capability.
- 5mo ago
Beta 473 (duplicate publish)
Cross-feed duplicate of beta.473 from the same day. No additional content.
View source ↗ - 5mo ago
Beta 471: multi-issue security hardening sweep
Beta.471 is a broad multi-issue security sweep: mass-assignment hardening, team-scoped queries, locked component properties, Docker network name validation, URL escaping. The volume of changes signals a coordinated audit pass rather than ad-hoc fixes.